Impact
A flaw in the rubygem-katello component permits a missing return statement after an unauthorized error to allow the request flow to continue into downstream business logic and database validation. This bypass lets an attacker glean the existence of Users, Organizations, and Products through differential HTTP responses, exposing internal state. The vulnerability does not grant direct code execution but enables critical information disclosure that can aid in further attacks.
Affected Systems
Red Hat Satellite 6 and Red Hat Satellite 6.19 for RHEL 9 are affected when they run the vulnerable rubygem-katello package. The issue applies to all nodes that expose the RegistryProxiesController endpoints, including Satellite Capsules and satellite utilities components tied to those versions.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. EPSS is not available, suggesting limited but possible exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation to date. The likely attack vector is remote, through crafted HTTP requests sent to the RegistryProxiesController endpoints. Detection may involve monitoring for repeated enumeration requests or unusual API traffic.
OpenCVE Enrichment